CONSTRUCTION-EVIDENCE, STATUTORY-ADJUDICATION & PROFESSIONAL-ADVICE DISCLAIMER — READ FIRST
ClaimLedger is a site-evidence capture, hidden-works-protection and claim-ready PDF pack tool for specialty subcontractors and owner-operator trades. It is NOT an RICS quantity-surveying instrument; NOT a CIOB, CIArb, RIBA, CIBSE, CABE, ICE, IStructE, CIPHE, IOR, AIQS, AIB, NZIQS, ASPE or equivalent professional-body attestation; NOT a solicitor's, barrister's, notary's or licensed conveyancer's instrument; NOT a court, tribunal, statutory-adjudicator, arbitrator or expert-determination ruling; NOT a Qualified Trust Service Provider or eIDAS qualified electronic signature / seal / timestamp service within the meaning of Regulation (EU) 910/2014; NOT a project-management, scheduling, drawing / BIM / ISO 19650 common-data-environment, estimating, invoicing, payments, timesheet or accounting system; NOT a Land Registry, HMRC, IRS, ATO, VMI or other public-administration filing instrument; NOT a fire alarm, intrusion alarm, gas / smoke / carbon-monoxide detector, calibrated dimensional / thermal / moisture / tension / torque / pressure-test / lux instrument or NFPA fire-marshal instrument; and NOT a public emergency service. CALLING 999 / 112 / 911 / 000 OR THE LOCALLY APPLICABLE PUBLIC EMERGENCY NUMBER REMAINS MANDATORY whenever any person is in apparent danger of death or serious harm on site (electrocution, fall from height, trench or excavation collapse, structural collapse, plant / vehicle strike, arc-flash, hot-works burn, confined-space entrapment, asphyxiation, hazardous-substance exposure, fire, explosion or medical emergency).
ClaimLedger does NOT provide legal, contractual, quantity-surveying, valuation, entitlement, statutory-adjudication, mediation, arbitration, litigation, tax, insurance, planning-permission, building-control, fire-marshal or health-and-safety advice, opinion, determination or attestation. It does NOT compute or advise on the value of any interim payment application, variation, retention release, defect resolution, back-charge, prolongation cost, disruption cost, loss of profit, loss of overhead, finance charge, delay-analysis quantum or any other commercial or damages figure. It does NOT compute or advise on any statutory deadline under the U.K. Housing Grants, Construction and Regeneration Act 1996 (as amended by the Local Democracy, Economic Development and Construction Act 2009) and the Scheme for Construction Contracts (England and Wales) Regulations 1998 or its Scottish / Northern Irish equivalents; the Irish Construction Contracts Act 2013; the Australian Building and Construction Industry Security of Payment Acts (NSW 1999, Vic BIF Act 2020, Qld BIF Act 2017, WA CCA, SA / Tas / NT / ACT); the U.S. Miller Act (40 U.S.C. §§ 3131-3134), state prompt-payment acts and state mechanic's-lien laws; or the German BGB §§ 631 ff., VOB/B, Bauforderungssicherungsgesetz (BauFordSiG) and Bauhandwerkersicherungshypothek regimes. It does NOT interpret, opine on or discharge any obligation under the JCT, NEC3 / NEC4, FIDIC, IChemE, ACA, GC Works, PPC 2000 / FAC-1, ConsensusDocs, AIA, AGC, DBIA, EJCDC, VOB/B, ÖNORM B 2110, AS 4000, AS 2124 or any other standard-form or bespoke construction contract. It does NOT constitute an HSE, CDM 2015, OSHA (29 CFR §1926 and §1910), U.K. Building Safety Act 2022, Building Regulations, planning-permission, fire-marshal or asbestos / lead / silica / vibration / noise / manual-handling risk assessment. It does NOT constitute a Modern Slavery Act 2015 statement, EU CSDDD filing, German LkSG declaration, U.K. Bribery Act / U.S. FCPA compliance attestation, 5AMLD / 6AMLD / OFAC / EU / U.K. OFSI sanctions screening or Construction Industry Scheme (CIS) tax submission.
Local notifications, ActivityKit Live Activities, pack completeness-check flags, Foundation Models on-device dictation-structuring outputs, Vision-framework on-device OCR outputs (v1.1) and SHA-256 photo-hash manifests are operational reminders and evidentiary records only — ADVISORY ONLY. The Subscribing Customer, its owner / managing director, its foremen and its professional advisers (solicitors, barristers, RICS chartered quantity surveyors, adjudicators, arbitrators, mediators, claims consultants, engineers, insurance brokers, loss adjusters, CDM Principal Designers, CDM Principal Contractors, HSE Competent Persons, fire-safety engineers and tax advisers) remain the responsible persons for every commercial, contractual, statutory-adjudication, legal, valuation, entitlement, quantum, delay, disruption, defects, retention, handover, health-and-safety, CDM, planning, building-control, fire-safety, insurance, tax, AML, sanctions, modern-slavery, employment and contractual decision at all times — independently of the App.
AT A GLANCE — what you should know in 60 seconds
• We do not sell your personal data and we never will. In fact, ML Consulting collects no Customer Data on its own infrastructure at all: ClaimLedger is a no-server, offline-first iPhone-and-iPad application, and every Customer Data category — photo sets, per-photo SHA-256 hashes, GPS coordinates, timestamps, recorder identity, dictated notes, Foundation Models on-device dictation-structuring output, PencilKit markup, work packages, projects, hidden-works entries, covering-event records, variation records, defect records, daily-log entries, claim-calendar entries, PackRecord logs, PDF Pack renders, RoomPlan sketches (v1.5+) and Vision OCR outputs (v1.1) — lives in the Subscribing Customer's own Apple iCloud (CloudKit private database and, for v1.1 CKShare team workspaces, the CKShare zone). We do not use Subscriber Data to train, fine-tune, evaluate or benchmark any general-purpose, construction-evidence, dictation, OCR, photo-verification, worker-performance or claim-outcome machine-learning model.
• ClaimLedger is offline-first. Capture, browsing, pack generation, hidden-works follow-up notifications, application-day reminders, dispute-window Live Activities and every other operational flow work with zero connectivity; CloudKit syncs when your device is next online, on your own iCloud account. If iCloud is unavailable, the App runs in local-only mode with a visible banner and no work is lost.
• ClaimLedger operates no server, no web portal, no App Clip surface, no operator dashboard, no third-party analytics SDK, no crash-reporting SDK, no advertising SDK, no attribution SDK and no tracking SDK. The Privacy Manifest declares this. The App Store “Data Not Used to Track You” declaration reflects it. There is no ad model and there never will be. There are no streaks, no shareable moments, no marketing-style nudges and no anxiety-triggered notifications.
• ClaimLedger is sold by subscription through the Apple App Store: Pro at €14.99 per month or €99.99 per year (single owner, whole-company use, v1.1 foreman participants free), and — from v1.1 — Trade tier at approximately €39.99 per month or €299 per year (more active projects, more participant seats, branded and head-contractor pack templates, CSV import / export). A 14-day full-featured trial applies. Post-trial the App is read-only with export always available; your data is never held hostage. All billing runs through Apple App Store In-App Purchase (StoreKit 2); ML Consulting operates no direct billing channel.
• The App is NOT an RICS quantity-surveying instrument, NOT a CIArb tribunal, NOT a court / tribunal / statutory-adjudicator ruling, NOT a Qualified Trust Service Provider under eIDAS, NOT a project-management / scheduling / drawing / BIM / ISO 19650 common-data-environment system, NOT an estimating / invoicing / payments / timesheet / accounting system, NOT a Land Registry / HMRC / IRS / VMI filing instrument, NOT a fire alarm, NOT an intrusion alarm, NOT a calibrated dimensional / thermal / moisture / tension / torque / pressure-test instrument, NOT a CDM 2015 Principal Designer / Principal Contractor duty-holder submission and NOT a public emergency service.
• Face ID / Touch ID-gated pack generation, PencilKit handover signatures (typed name and role recorded), Apple-Pencil markup on photos, shared-device PIN entries and per-photo SHA-256 + timestamp + GPS anchors are operational, evidentiary acknowledgements only — they may, depending on context, qualify as electronic signatures or advanced electronic signatures under eIDAS (Regulation (EU) 910/2014); they qualify as qualified electronic signatures only where combined with a qualified certificate issued by a qualified trust service provider, which ClaimLedger does not do. Photo-hash manifests are a fingerprint, not a notarisation.
• Project, package, evidence, hidden-works, variation, defect, handover, retention and Pack data belongs to the Subscribing Customer. We do not share or sell this data with any third party for advertising, commercial-intelligence, valuation-benchmarking, market-research, insurance-aggregation, credit-scoring, worker-performance-scoring or claim-outcome-prediction purposes.
• ClaimLedger deliberately does NOT offer: AI quantum, entitlement, valuation, delay-analysis, disruption-analysis, prolongation-cost, back-charge, retention, variation, defect-attribution or Pack-outcome computations; AI statutory-adjudication or court-outcome predictions; AI RICS / CIOB / CIArb / RIBA / CIBSE / ICE / IStructE professional-body attestations; AI CDM 2015 / HSE / OSHA / BauFordSiG / Building Safety Act 2022 duty-holder submissions; AI planning-permission, building-control or fire-marshal decisions; AI JCT / NEC / FIDIC / IChemE / ACA / GC Works / ConsensusDocs / AIA / VOB/B / AS 4000 / AS 2124 contract-clause interpretation; AI Bribery Act, FCPA or OECD anti-corruption determinations; AI sanctions or PEP determinations; AI Construction Industry Scheme (CIS) / HMRC / IRS / VMI / ATO tax determinations; AI Modern Slavery Act, CSDDD or LkSG declarations; AI worker-performance, employability, ranking, blacklist or workplace-behaviour profiles of any owner, foreman, apprentice, labourer, hired-in operative, head-contractor QS, adjudicator, insurer, claims consultant, employer's agent, project manager, engineer or any other individual. The AI helpers we do offer (on-device Foundation Models dictation structuring with plain-transcript fallback below the device floor; on-device Vision OCR of written site instructions and delivery notes in v1.1; and deterministic Pack completeness checks) are on-device only, never autonomous, raw input always retained.
• You can exercise the full set of EU GDPR rights at any time by writing to support+claimledger@mlconsulting.lt. Our lead supervisory authority is the Lithuanian State Data Protection Inspectorate (VDAI) in Vilnius. Where the only copy of your Customer Data lives in your own iCloud, many rights are exercised through Apple (iCloud account controls, Data & Privacy portal at privacy.apple.com) rather than through ML Consulting.
• ClaimLedger is intended for business users (B2B) only. Users must be at least 18 years old, must be responsible for or delegated by the owner / managing director of the Subscribing Customer, must hold role-appropriate qualifications, professional-body memberships, CDM 2015 / HSE / OSHA / BauFordSiG training, tool-and-plant licences and site inductions before capturing on any project, and must comply with the site rules, employment obligations and worker-monitoring rules of every jurisdiction in which the Subscribing Customer operates.
1. About this Privacy Policy
ML Consulting MB (“ML Consulting”, “we”, “us”, “our”) is the publisher of the ClaimLedger iOS / iPadOS application (the “App”), distributed exclusively through the Apple App Store. This Privacy Policy explains what personal data the App processes — and, importantly, where that data lives, which is the Subscribing Customer's own Apple iCloud rather than any server operated by ML Consulting — when you download, install, open, sign in with your Apple Account, subscribe, capture a photo set with the AVFoundation camera surface, tag a photo set as hidden-works before a covering event, dictate a structured note with the on-device Foundation Models framework (with plain-transcript fallback on devices below the Foundation Models floor), mark up a photo with PencilKit, OCR a written site instruction or delivery note with Vision (v1.1), record a variation, log a defect, sign a handover on a receiving party's screen with PencilKit, generate a Valuation / Progress Pack, a Variation Pack, a Retention Release Pack, a Defects Resolution Pack, a Handover Pack or an Adjudication Bundle, share a Pack PDF through the iOS share sheet to a head-contractor Quantity Surveyor / adjudicator / insurer / claims consultant / employer's agent / project manager / accounts-payable team, join or accept a v1.1 CKShare team invite as a foreman, start an owner-entered dispute-window countdown as an ActivityKit Live Activity, or otherwise use the App — why we process it, the legal bases on which we rely, with whom we share it, for how long we keep it, and the rights you have under the GDPR and other applicable privacy laws.
This Policy is written to satisfy Articles 12 to 14 of Regulation (EU) 2016/679 (the GDPR), the Republic of Lithuania Law on Legal Protection of Personal Data, Article 88 GDPR (processing in the context of employment), Regulation (EU) 910/2014 (eIDAS) where electronic-signature claims are concerned, Regulation (EU) 2024/1689 (the AI Act) where transparency and human-oversight obligations apply to Foundation Models dictation structuring and Vision-framework OCR, and the applicable construction-and-payment framework of every launch market — the U.K. HGCRA 1996 / Scheme for Construction Contracts 1998 / LDEDCA 2009; the Irish Construction Contracts Act 2013; the Australian SoP Acts of every state and territory; the U.S. Miller Act, state prompt-payment acts and state mechanic's-lien laws; and the German BGB §§ 631 ff., VOB/B, BauFordSiG and Bauhandwerkersicherungshypothek regimes.
ClaimLedger is intended for business users (B2B) only — specialty subcontractors and owner-operator trades with 1-15 staff (mechanical, electrical, plumbing / HVAC, drywall and fit-out, tiling, waterproofing, groundworks, façade, roofing, insulation, steel-fixing, formwork, joinery, painting, flooring, glazing, cladding, ceilings, partitions and equivalent specialty trades) and solo trades who are their own foreman. This Policy should be read together with the ClaimLedger Terms and Conditions (Master Terms + Schedule A) published by ML Consulting MB.
2. Controller identification
We are the data controller for the processing described as “we act as controller” in section 4. Because ClaimLedger operates no server, no web portal and no App Clip surface, and because Customer Data lives in the Subscribing Customer's own iCloud rather than on ML Consulting infrastructure, the controller-level processing we carry out is deliberately narrow.
• Legal name: ML Consulting MB
• Legal form: Mažoji bendrija (small partnership) governed by the law of the Republic of Lithuania
• Legal entity code: 306991112 (Centre of Registers of the Republic of Lithuania)
• Website: https://mlconsulting.lt
• Privacy contact: support+claimledger@mlconsulting.lt
ML Consulting MB has not designated a Data Protection Officer because its current processing does not meet the criteria in Article 37(1) GDPR. The privacy contact above handles all data-protection enquiries.
Our lead supervisory authority for the purposes of the GDPR's one-stop-shop mechanism (Article 56 GDPR) is the Lithuanian State Data Protection Inspectorate — Valstybinė duomenų apsaugos inspekcija (VDAI) — at L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania, telephone +370 5 271 2804, email ada@ada.lt, website vdai.lrv.lt.
3. Scope of this Policy
This Privacy Policy applies to:
• the ClaimLedger iOS / iPadOS application published by ML Consulting MB on the Apple App Store, including the iPhone TabView capture-first surface (Today · Capture · Evidence · Packs · Settings), the iPad NavigationSplitView review-cockpit surface, the Foundation Models on-device dictation-structuring surface, the Vision-framework OCR surface (v1.1), the PencilKit markup and handover-signature surface, the CoreLocation GPS geotagging surface, the CryptoKit per-photo SHA-256 hashing surface, the LocalAuthentication Face ID / Touch ID gate on pack generation, the PDFKit Pack render pipeline (Valuation / Progress Pack, Variation Pack, Retention Release Pack, Defects Resolution Pack, Handover Pack, Adjudication Bundle), the ActivityKit Live Activity for owner-started dispute-window countdowns, the local-notification calendar, the v1.1 CKShare team workspace (owner subscribes; foremen join as capture-only participants) and the RoomPlan sketch surface reserved for v1.5+ on LiDAR-equipped devices;
• user accounts, subscriptions (Pro at €14.99 per month or €99.99 per year, and — from v1.1 — Trade tier at approximately €39.99 per month or €299 per year), 14-day trials, post-trial read-only-with-export mode, StoreKit 2 In-App Purchase billing and App Store Server Notifications;
• the App's landing pages, help articles and documentation hosted on mlconsulting.lt that describe ClaimLedger; and
• email and other communications you exchange with us about the App.
This Policy does NOT apply to the recipient side of Pack delivery. When you export a Pack PDF from the iOS share sheet — to email, to Files, to a head-contractor Quantity Surveyor, to an adjudicator, to an insurer, to a claims consultant, to an employer's agent, to a project manager, to an accounts-payable team or to any other counterparty — the PDF becomes a document under the recipient's control, processed by the recipient's own systems. ML Consulting has no visibility into and no processing role in the recipient's handling of that PDF.
Where Apple Inc. or its subsidiaries, or any other independent third party, processes personal data on its own account in connection with the App — for example, the Apple App Store, iCloud, CloudKit (private database and CKShare zones), Sign in with Apple, StoreKit 2 In-App Purchase, APNs push, ActivityKit, WidgetKit, the Foundation Models framework, the Vision framework, the Speech framework, PhotoKit, PencilKit, CryptoKit, the Secure Enclave, LocalAuthentication, PDFKit, RoomPlan or the Apple Weather service — that party acts as a separate controller and its own privacy policy applies in addition to this Policy.
4. Our two privacy roles — controller and processor
4.1 We act as controller
We determine the purposes and means of processing for the following narrow categories:
• the Apple-supplied account identifier and either your real email address or an Apple-generated relay address (“Hide My Email”) that Sign in with Apple returns;
• device, technical, telemetry and security-event data the App generates during normal use (limited: crash reports if you have opted in to Diagnostics and Usage Data at the OS level, iOS / iPadOS version, App version, language and timezone);
• communications and support correspondence about the App;
• billing and payment data returned to us by App Store Server Notifications (subscription identifier, tier, renewal state, trial state, refund state); Apple Inc. is the merchant of record; and
• the internal logs we keep to comply with statutory accounting and tax retention under Lithuanian law.
4.2 We act as processor (Customer Data lives in your own iCloud)
Unlike most of the ML Consulting portfolio, ClaimLedger has no EU-resident backend and no ML-Consulting-operated database. Every category of Customer Data lives in the Subscribing Customer's own Apple iCloud (CloudKit private database and, for v1.1 CKShare team workspaces, the CKShare zone) on the Subscribing Customer's own iCloud quota. In local-only mode (when iCloud is unavailable) it lives only on the device.
The consequence for privacy roles is unusual: for these categories, ML Consulting acts as processor on the Subscribing Customer's instructions insofar as our App code runs on the Subscribing Customer's device, but ML Consulting never itself sees, receives, stores, transmits, indexes, aggregates or otherwise processes the underlying content of that Customer Data on its own infrastructure. Apple Inc., in operating iCloud and CloudKit on behalf of the Subscribing Customer, is a separate independent controller for its own iCloud-side processing. Where a foreman joins a v1.1 CKShare team workspace as a capture-only participant, the owner (Subscribing Customer) remains the data controller and ML Consulting acts as processor in the same narrow sense.
ML Consulting does not use Subscriber Data to train, fine-tune, evaluate or benchmark any machine-learning model — because ML Consulting never receives Subscriber Data on its own infrastructure. Foundation Models is Apple's on-device large-language-model framework; its inference runs locally and its output does not leave the device as a result of the App's use.
5. Apple App Store, iOS, iPadOS, CloudKit, Foundation Models, Vision, Speech, PencilKit, CryptoKit platform context
Because the App is delivered through the Apple App Store, runs on Apple's iOS and iPadOS platforms and — critically — stores every Customer Data category in the Subscribing Customer's own Apple iCloud rather than on any ML Consulting server, this section makes the platform inheritance explicit. There is no web portal, no App Clip surface, no operator dashboard, no Mac Catalyst app, no Android app, no watchOS companion and no visionOS surface within the scope of the App.
5.1 App Privacy details on the App Store
Apple requires every application on the App Store to publish a structured summary of the data it collects. ClaimLedger's App Privacy details declare exactly what the App collects — User Content (photo sets stored in your iCloud), Precise Location (When in Use, for photo geotags), no tracking, no third-party SDKs — and, as the App Store submission and the review notes both make explicit, ML Consulting the developer collects nothing on its own infrastructure; all Customer Data lives in the customer's iCloud.
5.2 App Tracking Transparency
ClaimLedger does not track you across other companies' applications and websites within the meaning of Apple's App Tracking Transparency framework. We do not request the ATT permission and we do not use the iOS Identifier for Advertisers (IDFA). The App's App Store declaration is set to “Data Not Used to Track You”. We never apply worker-performance, employability, ranking, blacklist, counterparty-risk or claim-outcome-prediction profiling.
5.3 Privacy Manifest
ClaimLedger ships an Apple-required Privacy Manifest (PrivacyInfo.xcprivacy) declaring the data categories the App accesses, the reasons for any use of “required reason” iOS APIs (camera, photo library, CoreLocation, Speech, Foundation Models, Vision, PencilKit, CryptoKit, Keychain, LocalAuthentication, PDFKit, BackgroundTasks, StoreKit 2, RoomPlan in v1.5+) and the third-party SDKs the App depends on — which, deliberately, is none.
5.4 iOS sandbox, Data Protection, CryptoKit hashes and the append-only evidence model
On-device application data is held inside the iOS application sandbox and benefits from Apple's default Data Protection. Every photo captured through the App carries a CryptoKit SHA-256 hash computed at capture time before the UI unblocks; every evidence entry is append-only after save, corrections supersede rather than overwrite, and Packs disclose supersede chains. The photo-hash manifest carried in every Pack is a fingerprint, not a notarisation.
5.5 Sign in with Apple, ambient iCloud identity and shared-device PIN
The App relies on ambient iCloud identity for CloudKit private-database access. Sign in with Apple is supported in line with Apple's App Store Review Guidelines § 4.8 when we need a stable account identifier separate from the device's iCloud state. If iCloud is unavailable, the App runs in local-only mode with a visible banner and no work is lost; on the next iCloud reconnection, the App syncs the accumulated local records to the Subscribing Customer's own CloudKit private database. Foreman participants in v1.1 CKShare workspaces authenticate on their own device with their own Apple ID.
5.6 Face ID, PencilKit handover signature and Apple-Pencil markup — not eIDAS qualified
Face ID- / Touch ID-gated Pack generation, PencilKit handover signatures with typed name and role, Apple-Pencil markup and per-photo SHA-256 hash chains are operational, evidentiary acknowledgements. They may qualify as electronic signatures or advanced electronic signatures under eIDAS; they qualify as qualified electronic signatures only where combined with a qualified certificate issued by a qualified trust service provider, which ClaimLedger does not do. They are NOT a notarial deed, NOT a court order, NOT a statutory-adjudicator's decision, NOT a Qualified Trust Service Provider attestation, NOT a Land Registry / HMRC / IRS / VMI filing, NOT an RICS / CIOB / CIArb professional-body attestation, NOT a CDM 2015 / HSE / OSHA duty-holder determination, NOT a calibrated instrument reading and NOT a planning-permission or building-control approval.
5.7 iPhone and iPad only — no watchOS, no Mac, no Android, no web, no App Clip
The App is designed for iPhone as the site capture surface (one-handed, glove-tolerant, cold-start-to-camera under 2.5 seconds, routine capture under 15 seconds) and iPad as the review cockpit for application-day preparation. There is no watchOS companion, no native Mac app, no Mac Catalyst app, no Android app, no web app, no App Clip surface and no server-hosted portal. Recipients of Packs receive PDFs by email or share sheet; App Clips are deliberately excluded because App Clips cannot write to CloudKit.
5.8 AVFoundation, PhotoKit and CoreLocation
ClaimLedger uses AVFoundation and PhotoKit for the camera and photo-library surfaces. Every captured photo carries a CoreLocation GPS coordinate at capture time when the “When in Use” location permission has been granted, plus a weather snapshot auto-attached from the entry's own capture metadata. The App does NOT perform continuous background location tracking and is not a fleet / vehicle / worker tracker.
5.9 Foundation Models — on-device dictation structuring with plain-transcript fallback
ClaimLedger uses Apple's Foundation Models framework on-device to structure dictated capture notes into the fields the recorder confirms. Where the device is below the Foundation Models floor, or Foundation Models is unavailable, the App falls back to a plain Speech-framework transcript and manual field entry. Foundation Models inference runs locally on your device and its input and output do not leave the device as a result of the App's use. The recorder explicitly confirms every structured field.
5.10 Vision framework — on-device OCR (v1.1)
From v1.1, ClaimLedger uses the Vision framework on-device to OCR written site instructions and delivery notes. Vision OCR runs locally on your iPhone or iPad; OCR text attaches to the parent variation or delivery entry as a suggestion the user confirms. OCR is NOT a notarial transcription, NOT a court-admissible certified copy and NOT a CIS / HMRC / IRS / VMI submission.
5.11 PencilKit, ActivityKit, APNs, EventKit, WidgetKit, App Intents, BackgroundTasks, StoreKit 2 and Focus Filter API
ClaimLedger relies on PencilKit (photo markup, handover signatures); APNs local notifications (application-day 3-days-before and day-of reminders; hidden-works follow-up; trial reminders; optional daily-log nudges — operational only, sober, never marketing); ActivityKit Live Activities (Owner-started dispute-window countdown with Owner-entered dates); WidgetKit (Lock Screen widget for next application day); App Intents and AppShortcuts (Siri shortcuts to Capture, Today, Application Pack, Hidden-Works Register); BackgroundTasks (hidden-works follow-up scheduling, iCloud reconnection sync); StoreKit 2 (Apple App Store In-App Purchase); the Focus Filter API.
5.12 CloudKit private database and CKShare (v1.1) — Customer Data in your own iCloud
Every category of Customer Data lives in the Subscribing Customer's own Apple iCloud, in the CloudKit private database for the ClaimLedger container. Photos, PDFs, RoomPlan sketches and other binary assets are stored as CKAssets on the Subscribing Customer's own iCloud quota. From v1.1, team workspaces are implemented via CKShare: the owner subscribes and creates one CKShare per company root; foremen accept the share link, install the App and join as capture-only participants; participants never see the paywall; capture-only enforcement is app-level; removing a participant preserves that participant's entries in the owner's workspace; owner deletion removes the zone and share after offering full export; participant deletion leaves company data intact.
5.13 RoomPlan (v1.5+, LiDAR devices only) — sketch, not measurement authority
From v1.5+, and only on LiDAR-equipped iPhone Pro and iPad Pro models, ClaimLedger will offer a RoomPlan as-built room capture for fit-out handover packs. Any output produced through RoomPlan is a floor-plan sketch attached to an evidence entry — it is NOT a calibrated dimensional-survey instrument, NOT a laser-scan point-cloud instrument, NOT an ISO 19650 common-data-environment output, NOT a RICS Measured Survey and NOT a Building Regulations / planning-permission submission.
5.14 App Privacy Report
iOS 15.2 and later provide an in-operating-system App Privacy Report. ClaimLedger is designed so that this report shows the Apple platform domains used (App Store, iCloud, CloudKit, APNs) and — deliberately — nothing else. In particular, no ML Consulting server domain, no third-party analytics domain, no advertising domain, no attribution domain and no crash-reporting domain should ever appear.
6. Key terms used in this Policy
• Personal data — any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
• Processing — any operation performed on personal data.
• Controller — the person who determines the purposes and means of processing.
• Processor — a person who processes personal data on behalf of a controller.
• Subscribing Customer — the business customer (a specialty subcontractor or owner-operator trade with 1-15 staff, or a solo trade) that took out the ClaimLedger Pro or Trade-tier subscription.
• Owner (Principal) — the owner or managing director of the Subscribing Customer, who holds the App Store subscription.
• Foreman participant — a natural person authorised by the Owner (from v1.1) to join the company's CKShare zone as a capture-only participant.
• Company workspace — the Subscribing Customer's single CloudKit private database (and, from v1.1, CKShare zone) on the Subscribing Customer's own iCloud quota.
• Project — a construction contract or subcontract that the Subscribing Customer is delivering.
• Work package — a scope subdivision of a Project (for example, “Apt 3.02 first fix”, “Riser B”, “Roof waterproofing”).
• Evidence entry — an append-only record capturing one or more photos anchored to a Work package, with SHA-256 per photo, timestamp, GPS, recorder identity, type tag (progress / hidden works / variation / defect / delivery / general).
• Hidden-works register — the Project-scoped register of every evidence entry marked about-to-be-covered, paired with its covering-event record.
• Variation record — an entry describing an instruction (verbal / written / drawing revision) with linked before / during / after evidence and a status field.
• Defect record — an entry describing an alleged defect with raised-by, description, linked evidence, status and rectification evidence.
• Daily log — a one-tap day note per Project.
• Claim calendar — the per-Project application day with local-notification reminders and, when the Owner starts one manually, a Live Activity dispute-window countdown with Owner-entered dates.
• Pack — a PDF assembled on-device by PDFKit in one of six types: Valuation / Progress Pack, Variation Pack, Retention Release Pack, Defects Resolution Pack, Handover Pack, Adjudication Bundle. Every Pack carries the mandatory Section I disclaimer: “This document is a record of entries made by the named users. It is documentation, not legal, contractual or quantity-surveying advice. Generated by ClaimLedger v[x] on [date].”
• PackRecord — the append-only record of every Pack generation.
• Pack completeness check — the deterministic checklist run before Pack generation. Flags inform the Owner; they never block generation.
• Handover signature — a PencilKit signature captured on the Owner's device from a receiving party at a handover moment, with typed name and role recorded.
• Dispute-window countdown — an Owner-started ActivityKit Live Activity with dates entered by the Owner. The App tracks Owner-entered dates; it does not advise on statutory deadlines.
• Recipient — the head-contractor Quantity Surveyor, adjudicator, arbitrator, mediator, employer's agent, project manager, insurer, insurance broker, loss adjuster, claims consultant, solicitor, barrister, engineer, accounts-payable team or main-contractor commercial team who receives a Pack PDF via the iOS share sheet. Not a user of the App.
• On-device — data stored or processed locally on the Owner's or foreman participant's iPhone or iPad inside the iOS application sandbox.
• Sub-processor — a third-party service provider that processes personal data on our behalf. ClaimLedger deliberately depends on none for its data plane.
• EEA — the European Economic Area.
• VDAI — Valstybinė duomenų apsaugos inspekcija, the Lithuanian State Data Protection Inspectorate.
7. Personal data we process
This section describes the data ClaimLedger processes. The unusual feature to hold in mind: with the narrow exceptions in section 4.1, the Customer Data below lives in the Subscribing Customer's own iCloud, not on ML Consulting infrastructure. We do not receive, index, aggregate or otherwise process the content of that data ourselves.
7.1 Account and authentication data (we act as controller for the narrow subset)
Sign in with Apple identifier; Apple-issued relay address where you used “Hide My Email”; the ambient iCloud identity used by CloudKit (Apple is the controller for that); the App Store subscription identifier; the tier (Pro or Trade); trial state, renewal state, refund state as returned by App Store Server Notifications. We do not store passwords.
7.2 Device, technical and telemetry data (we act as controller — limited)
iOS / iPadOS version, device model, App version, language and timezone (visible to us only through App Store analytics reports Apple publishes to developers); IP address (only where the App makes a network call to our support endpoints). Pseudonymised interaction events are NOT collected — there is no third-party analytics SDK, no crash-reporting SDK, no attribution SDK.
7.3 Communications and support data (we act as controller)
The content and metadata of any email, support ticket, in-app help message, demo request, application-day support enquiry, hidden-works follow-up enquiry, Pack-generation enquiry, dispute-window enquiry or other correspondence with us, including any attachments you choose to send.
7.4 Billing and payment data (we act as controller; Apple is the merchant of record)
App Store Server Notifications payloads: subscription identifier, tier, trial state, renewal state, refund state, environment (sandbox / production), transaction identifier. We do not receive your payment-card data; Apple Inc. is the merchant of record. There is no direct billing channel and no Stripe / PayPal / GoCardless / bank-transfer path for ClaimLedger.
7.5 Customer Data (lives in your own iCloud; we act as processor in the narrow sense)
Company profile (name, logo, trade, timezone); Projects (client / head-contractor name, site address, application day-of-month, optional retention note, optional defects-period end date); Work packages per Project; Evidence entries (photos with per-photo SHA-256, timestamp, GPS coordinate at capture time, recorder identity, type tag, optional Foundation Models-structured dictated note or plain-transcript fallback, optional PencilKit markup, auto-attached weather); Hidden-works entries with covering-event pairing; Variation records with instruction reference and linked before / during / after evidence and status; Defect records with linked evidence and status; Daily logs; Claim-calendar entries; Handover signatures (PencilKit stroke, typed name, typed role, timestamp); PackRecord entries; PDF Pack renders as CKAssets; RoomPlan sketches as CKAssets (v1.5+); Vision OCR outputs (v1.1) as suggestion text attached to the parent entry.
7.6 Foreman participant personal data (from v1.1 CKShare workspaces)
Where the Owner invites a foreman under v1.1: the foreman's name, iCloud identity as supplied to the Owner's CKShare zone by Apple, capture-only role, join timestamp, entries captured by that foreman. The App does not verify a foreman's site inductions, CDM 2015 training, HSE Competent Person designation, OSHA competent-person designation, plant / tool licences, IPAF / PASMA / ANSI A92 / ISO 18893 MEWP credentials, first-aid / hot-works / confined-space / working-at-height / asbestos / lead / silica / manual-handling / hand-arm-vibration training or CSCS / CCNSG / SafePass / White Card credentials; the Owner is responsible.
7.7 Head-contractor QS, adjudicator, insurer and other Recipient data (incidental)
Where the Owner enters a Recipient's email address into the iOS share sheet at Pack export, that address is handled by iOS Mail (or the chosen share-target app), not by ClaimLedger; we do not store Recipient contact data server-side (because we have no server) and typically do not store it in Customer Data at all unless the Owner records it inside a Project.
7.8 Site-personnel and third-party personal data (incidental in evidence photos)
Where an evidence photo incidentally captures a foreman, apprentice, labourer, hired-in operative, delivery driver, site visitor, member of the public, head-contractor supervisor, engineer, architect, employer's agent, project manager or any other person on or near the site: the photograph and its association with the parent Evidence entry. Treated as Customer Data on the Subscribing Customer's iCloud. The Owner is responsible for site signage, site rules and Article 88 GDPR obligations.
7.9 Special-category and sensitive data (Article 9 GDPR — incidental)
ClaimLedger is not designed to collect special-category data. Site evidence photos may incidentally reveal information about a person's ethnic origin, religious beliefs (visible religious jewellery or head-covering), trade-union membership (visible insignia on PPE), or health. The Subscribing Customer warrants that any incidental capture is proportionate to the construction-payment-evidence purpose and that the Subscribing Customer holds an appropriate lawful basis under Articles 6 and 9 GDPR. Biometric authentication (Face ID / Touch ID) is performed by Apple's LocalAuthentication framework and biometric data never leaves the device.
7.10 Camera, microphone, photo-library, Foundation Models, Vision and Speech-recognition permissions
Camera input for AVFoundation capture; microphone input for Foundation Models-structured dictation (with Speech-framework fallback below the device floor); photo-library input via PhotoKit only when the recorder explicitly imports an existing photo; PencilKit input for photo markup and handover signatures. All access is controlled by the iOS permission prompts and may be revoked at any time in iOS Settings.
7.11 Location data (CoreLocation — When in Use, per-photo at capture time)
Where you grant CoreLocation “When in Use” permission, a GPS coordinate is captured at the moment each photo is captured and stored alongside the Evidence entry. The App does NOT perform continuous background location tracking.
7.12 Weather data (auto-attached from capture metadata)
A weather snapshot (temperature, conditions, wind, precipitation) auto-attached from Apple Weather at the moment each photo is captured and stored alongside the Evidence entry, for daily-log context and for delay / obstruction records.
7.13 Apple Calendar (EventKit) integration
Where the Owner enables it, the App may write application-day reminders and, from v1.1, dispute-window milestones to the Apple Calendar. We do not read or transmit your wider Calendar contents.
7.14 Notification preferences and tokens
Local-notification cadence toggles (application-day 3-days-before and day-of reminders; hidden-works follow-up notifications; trial-day-11 and trial-day-13 reminders; optional daily-log nudges; owner-selected quiet hours); iOS notification permission state; ActivityKit Live Activity state.
7.15 What we do not collect
To remove ambiguity, ClaimLedger does not collect:
• the contents of your Apple Contacts, the wider Apple Calendar, your photo library beyond photos you actively import through PhotoKit, or any HealthKit / HomeKit data;
• data from any project-management, scheduling, drawing / BIM / ISO 19650 common-data-environment, estimating, invoicing, payments, timesheet or accounting system;
• behavioural-advertising identifiers; we do not run advertising, do not use the IDFA and do not share data with advertising networks;
• analytics, attribution or crash-reporting data through any third-party SDK — ClaimLedger deliberately embeds none;
• continuous background-location data; per-photo geotagging (where enabled) captures a GPS coordinate at the moment of capture only;
• any worker-performance, employability, ranking, blacklist, counterparty-risk or claim-outcome-prediction profile.
8. How we collect personal data
We collect personal data in three narrow ways:
1. Directly from you — when you create an account (via Sign in with Apple), install or use the App, subscribe through the Apple App Store, capture a photo set through AVFoundation, dictate a note through Foundation Models (or the Speech-framework fallback), OCR a written instruction with Vision (v1.1), mark up a photo with PencilKit, capture a handover signature with PencilKit, generate a Pack through PDFKit, start an Owner-entered dispute-window Live Activity, invite a foreman through CKShare (v1.1), contact support or subscribe to a communication.
2. Automatically through your use of the App — when the App generates on-device application data (Pack completeness-check output, hidden-works follow-up schedule, per-photo SHA-256 hashes, PackRecord entries); and when Apple platform services supply data linked to your action. Aside from App Store Server Notifications payloads and any support-endpoint hits, none of this data leaves the device.
3. From Apple — when Apple supplies us with the result of Sign in with Apple, when the App Store delivers an In-App Purchase result through StoreKit 2 and App Store Server Notifications, when App Store analytics reports Apple publishes to developers arrive, and when — for CloudKit and CKShare — Apple operates the Subscribing Customer's iCloud on the Subscribing Customer's behalf.
9. Why we process personal data and our legal bases
For each processing activity we rely on a lawful basis under Article 6(1) GDPR.
9.1 Performance of a contract (Article 6(1)(b))
• Provide and operate the App on your iPhone and iPad, including authentication, the capture-first surface, the review-cockpit surface, the hidden-works register, the variation / defect / daily-log / claim-calendar surfaces, on-device Foundation Models dictation structuring, on-device Vision OCR (v1.1), on-device PDFKit Pack generation and the CloudKit private-database sync to your own iCloud.
• Process payments and manage billing through Apple App Store In-App Purchase.
• Face ID / Touch ID gating of Pack generation, PencilKit handover-signature capture and Pack-share confirmations.
• v1.1 CKShare team workspace — Owner invites foremen; participant accept-share flow; participant-attributed Evidence entries.
• Deterministic Pack completeness check, Pack generation and PackRecord logging.
• Send service messages (security, billing, material change notices).
• Provide customer support and respond to enquiries.
9.2 Consent (Article 6(1)(a))
• Camera, microphone, photo-library, Speech-recognition and location access via the iOS prompts.
• CoreLocation per-photo GPS geotag at capture time.
• Local-notification cadence and ActivityKit Live Activity (Owner-started dispute-window countdown).
• Optional EventKit writes to Apple Calendar.
• Focus Filter API filtering of ClaimLedger notifications.
9.3 Compliance with a legal obligation (Article 6(1)(c))
• Statutory accounting and tax retention under Lithuanian law.
• Respond to data-subject requests and operate the GDPR rights workflow.
• Comply with legal, regulatory, tax and law-enforcement obligations.
9.4 Legitimate interests (Article 6(1)(f))
• CryptoKit per-photo SHA-256 hashing and append-only supersede-chain evidence integrity.
• Defend or pursue legal claims, including App Store subscription disputes, statutory-adjudication counterclaims, insurance subrogation, HSE / OSHA / CDM 2015 investigations, BauFordSiG investigations and U.K. Building Safety Act 2022 investigations.
Where we rely on legitimate interests under Article 6(1)(f) GDPR, we have carried out and documented a balancing assessment. Where we rely on consent under Article 6(1)(a) GDPR, you may withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
10. Offline-first architecture and no-server data model — Customer Data in your own iCloud
ClaimLedger is offline-first. Capture, browsing, hidden-works follow-up notifications, application-day reminders, dispute-window Live Activities and Pack generation all work with zero connectivity; on-device budgets are cold-start-to-camera under 2.5 seconds, routine capture under 15 seconds, evidence search under 1 second on 5,000 entries and monthly Pack render under 10 seconds on an A15 device. If iCloud is unavailable, the App runs in local-only mode with a visible banner. When iCloud is available again, CloudKit syncs the accumulated local records to the Subscribing Customer's own CloudKit private database on the Subscribing Customer's own iCloud quota.
ClaimLedger operates no ML-Consulting-hosted backend. No EU-resident managed Postgres, no signed-URL object storage, no server-side AI, no private GPU boundary, no RFC 3161 trusted-timestamp authority integration. Customer Data lives in the Subscribing Customer's own iCloud, which is operated by Apple Inc. under Apple's own privacy terms and Apple's own data residency choices for iCloud (which are made by Apple, not by ML Consulting, and typically follow the customer's Apple Account country of registration).
11. Subscribing Customers, Owners, foreman participants and Recipients
ClaimLedger is operated on a single-Owner-per-company subscription model. The Owner subscribes through the App Store, administers the company workspace, records Projects and Work packages, captures or supervises capture, generates Packs, invites foreman participants (from v1.1 under CKShare) and shares Pack PDFs to Recipients through the iOS share sheet. The Owner is responsible for ensuring that invited foreman participants receive an appropriate privacy notice, that the company holds a valid lawful basis for processing their personal data under Article 88 GDPR and the national rules implementing it, and that site signage indicates that photographic evidence is captured for construction-payment purposes wherever local law requires.
11.1 Worker monitoring under Article 88 GDPR and comparable employment law
Because photo geotags, per-photo timestamps, recorder-identity attribution, Foundation Models-structured dictated notes and daily-log entries can constitute employee monitoring in many EU jurisdictions, the Subscribing Customer is responsible for satisfying the worker-monitoring obligations of every jurisdiction in which the relevant Project operates. This includes Article 88 GDPR; the Republic of Lithuania Labour Code; the U.K. Employment Rights Act 1996, Data Protection Act 2018 and ICO Employment Practices Code; the Irish Data Protection Act 2018 and Workplace Relations Commission guidance; the Australian Fair Work Act 2009 and state workplace-surveillance Acts (Workplace Surveillance Act 2005 (NSW), Surveillance Devices Act 1999 (Vic), Workplace Privacy Act 2011 (ACT) and equivalents); the U.S. National Labor Relations Act, state consent-to-record wiretap laws (California, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, Washington and equivalents) and state workplace-privacy statutes; the French Code du travail (articles L1121-1 and L1222-4); the German Betriebsverfassungsgesetz; the Italian Statuto dei lavoratori; and the rules of any applicable construction-sector collective bargaining agreement or trade-union recognition agreement (Unite the Union, GMB, CIJC, Construction Industry Wages Order and equivalents).
Before granting any foreman participant access, the Subscribing Customer must provide a privacy notice meeting Articles 13 to 14 GDPR and the national worker-information rules, consult representatives where required, establish and document an appropriate lawful basis, and use monitoring features proportionately and only for the construction-payment-evidence operational purpose described in the worker privacy notice. The App is not designed for, and must not be used for, covert worker surveillance.
11.2 Site-safety, CDM 2015 / HSE / OSHA / BauFordSiG and professional-body responsibility
The Subscribing Customer remains the appointed subcontractor, the contract counterparty, the CDM 2015 duty-holder appropriate to its role (Client, Principal Designer, Principal Contractor or Contractor as the case may be), the U.K. Health and Safety at Work etc. Act 1974 / MHSWR 1999 duty-holder, the U.S. OSHA 29 CFR §1926 duty-holder, the German Arbeitsschutzgesetz / Baustellenverordnung / BauFordSiG duty-holder, the Australian Work Health and Safety Act 2011 duty-holder or equivalent, the U.K. Building Safety Act 2022 duty-holder where the project is in scope, the legal employer of every foreman, apprentice, labourer and hired-in operative under its direction, and the party responsible for every payment application, variation, retention release, defects rectification, handover, dispute and adjudication reference at all times. The App does not transfer any of these duties to ML Consulting.
11.3 Recipients — no accounts, no App Clip, no server
Recipients — head-contractor Quantity Surveyors, adjudicators, arbitrators, mediators, employer's agents, project managers, insurers, insurance brokers, loss adjusters, claims consultants, solicitors, barristers, engineers, accounts-payable teams, main-contractor commercial teams and any other counterparty — do not have accounts in ClaimLedger. There is no App Clip surface (App Clips cannot write to CloudKit) and no operator dashboard. Recipients receive Pack PDFs via the iOS share sheet; once a Pack leaves your device, it is a document under the Recipient's control. ML Consulting has no visibility into and no processing role in the Recipient's handling of that PDF. The Owner is responsible for any confidentiality, contractual, professional-secrecy or trade-secret undertakings that apply to the Pack's contents at the moment of send.
11.4 Statutory-adjudication and dispute-window responsibility
Where the Owner starts a dispute-window Live Activity countdown, the dates in that Live Activity are entered by the Owner. ClaimLedger does not advise on, compute or track the statutory deadlines of the U.K. HGCRA 1996 / Scheme for Construction Contracts 1998 (7-day notice of adjudication, 28-day adjudication period, 14-day extension by the referring party, 100-day extension by joint agreement), the Irish Construction Contracts Act 2013, the Australian SoP Acts, the U.S. Miller Act 90-day notice-of-claim and 1-year suit-of-claim periods, the state prompt-payment-act deadlines, the state mechanic's-lien perfection deadlines or the German BGB / VOB/B / BauFordSiG deadlines.
12. Recipients of personal data
We share personal data only with the categories of recipients listed below, and only to the extent necessary for the purpose. We do not sell personal data, and we do not “share” personal data for cross-context behavioural advertising as that term is defined under California law. We do not share or sell Project, Work package, Evidence, hidden-works, variation, defect, daily-log, claim-calendar, handover-signature, PackRecord or Pack data with any third party for advertising, commercial-intelligence, valuation-benchmarking, market-research, insurance-aggregation, credit-scoring, worker-performance-scoring or claim-outcome-prediction purposes. Because ClaimLedger has no server, no third-party analytics SDK, no crash-reporting SDK, no advertising SDK, no attribution SDK, no tracking SDK and no direct billing channel, this list is deliberately short.
Categories of recipients:
• Apple Inc. and Apple Distribution International Limited — App Store distribution, App Store In-App Purchase (StoreKit 2), App Store Server Notifications, Sign in with Apple, ambient iCloud identity, iCloud, CloudKit private database, CKShare zones (v1.1), APNs local-notification delivery, ActivityKit Live Activities, WidgetKit, EventKit, App Intents / AppShortcuts, BackgroundTasks, PhotoKit, AVFoundation, PencilKit, PDFKit, CryptoKit and Secure Enclave, LocalAuthentication, Foundation Models, Vision framework, Speech framework, RoomPlan (v1.5+), CoreLocation, Apple Weather and every other Apple platform service on which the App depends. Independent controller for App Store-side, iCloud-side and Apple-platform-side processing.
• Recipients of Pack PDFs (head-contractor Quantity Surveyors, adjudicators, arbitrators, mediators, employer's agents, project managers, insurers, insurance brokers, loss adjusters, claims consultants, solicitors, barristers, engineers, accounts-payable teams, main-contractor commercial teams) — receive Pack PDFs sent from the Owner's iPhone or iPad via the iOS share sheet (typically as email attachments); process those PDFs on their own systems. No ClaimLedger account, no App Clip, no server-side portal. Independent controllers under their own professional, contractual, statutory-adjudication, insurer and confidentiality duties. Not sub-processors of ML Consulting.
• Professional advisers to ML Consulting (lawyers, accountants, auditors) — legal, tax, audit and employment advice on a need-to-know basis. Independent controllers under their own duties of confidence.
• Authorities, courts and regulators — where we are required by law, court order or a binding regulatory request, including the Lithuanian State Data Protection Inspectorate (VDAI), the Lithuanian State Tax Inspectorate (VMI) where applicable, the U.K. Information Commissioner's Office (ICO), Health and Safety Executive (HSE), Building Safety Regulator (BSR), the Irish Data Protection Commission (DPC), Health and Safety Authority (HSA) and Workplace Relations Commission (WRC), the Australian Information Commissioner (OAIC), Safe Work Australia and state adjudication registrars, the U.S. Federal Trade Commission (FTC), OSHA and state attorneys general, the German BfDI and Land-level DPAs, Bauaufsicht and Berufsgenossenschaft (BG BAU), and equivalents in every jurisdiction in which Projects operate. Independent controllers acting under their statutory powers.
• Successor entity — in the context of a merger, acquisition, restructuring or sale of assets, subject to confidentiality safeguards and to the buyer continuing to honour the commitments in this Policy. Independent controller after the transaction closes.
References in the App and in this Policy to the Royal Institution of Chartered Surveyors (RICS), Chartered Institute of Building (CIOB), Chartered Institute of Arbitrators (CIArb), Royal Institute of British Architects (RIBA), Chartered Institution of Building Services Engineers (CIBSE), Chartered Association of Building Engineers (CABE), Institution of Civil Engineers (ICE), Institution of Structural Engineers (IStructE), Chartered Institute of Plumbing and Heating Engineering (CIPHE), Institute of Refrigeration (IOR), Australian Institute of Quantity Surveyors (AIQS), Australian Institute of Building (AIB), New Zealand Institute of Quantity Surveyors (NZIQS), American Society of Professional Estimators (ASPE), American Institute of Constructors (AIC), Technology and Construction Solicitors' Association (TeCSA), Adjudication Society, Society of Construction Law, Society of Construction Arbitrators, Society of Construction Law Australia, Building Cost Information Service (BCIS), New Rules of Measurement (NRM), Standard Method of Measurement (SMM), Principles of Measurement (International — POMI), Deutsche Verdingungsordnung für Bauleistungen (DIN 1961 / VOB), Bauforderungssicherungsgesetz (BauFordSiG), FIDIC, JCT, NEC, IChemE, ACA, GC / Works, ConsensusDocs, AIA, AGC, DBIA, EJCDC, AS 4000, AS 2124, AS 4300 and equivalent standard-form contracts and professional bodies are descriptive only. None of those bodies endorses, certifies, audits, accredits or warrants the App or any Pack, and none is a partner, sub-processor, recipient or party to this Policy by virtue of being named.
A current list of our sub-processors, together with the country in which each provider operates, is published at mlconsulting.lt/legal/sub-processors and is updated when the list changes. For ClaimLedger specifically, the sub-processor list is deliberately empty: Apple Inc. is an independent controller for every Apple platform service on which the App depends, and ML Consulting engages no third-party data-plane sub-processor for ClaimLedger.
13. International data transfers
ML Consulting MB is established in Lithuania. Because ClaimLedger has no server and no ML-Consulting-hosted backend, the international-transfer question turns on Apple's iCloud residency for the Subscribing Customer's Apple Account and on the App Store's processing of billing data — both of which are choices made by Apple, not by ML Consulting, and are governed by the Subscribing Customer's own Apple Account terms and Apple's own privacy policy.
For the narrow controller-level data ML Consulting itself processes (Sign in with Apple identifiers, App Store Server Notifications payloads, support correspondence, billing / accounting records), we keep data in the European Union by default. Where personal data is transferred outside the EEA or the United Kingdom to a country that has not been the subject of an adequacy decision under Article 45 GDPR, we rely on one or more of the safeguards required by Chapter V GDPR, in particular:
• European Commission adequacy decisions, including the EU-US Data Privacy Framework where the recipient is certified under it;
• the European Commission's Standard Contractual Clauses (Module Two — controller to processor — and Module Three — processor to sub-processor), with the UK International Data Transfer Addendum or the UK International Data Transfer Agreement for transfers from the United Kingdom, and supplementary measures consistent with the European Data Protection Board's recommendations;
• additional technical measures including TLS 1.2 or higher for data in transit and Apple's iCloud encryption at rest, plus contractual and organisational measures appropriate to the sensitivity of construction-payment evidence; and
• any other lawful transfer mechanism under Articles 46 to 49 GDPR.
14. Automated decision-making and on-device ML — no backend AI
14.1 No solely-automated decisions with legal or similarly significant effects
We do not subject you to decisions producing legal effects concerning you or similarly significantly affecting you that are based solely on automated processing within the meaning of Article 22 GDPR. Where any aspect of a decision affecting you is informed by automated logic (for example, the deterministic Pack completeness-check flagging a package with no recent evidence), a human — the Owner or the recorder — is meaningfully involved in the outcome, and completeness-check flags never block Pack generation.
14.2 Explicit AI exclusions
ClaimLedger does NOT offer:
• AI valuation, entitlement, quantum, delay-analysis, disruption-analysis, prolongation-cost, back-charge, retention, variation, defect-attribution, adjudication-outcome, arbitration-outcome, court-outcome or Pack-outcome computations;
• AI statutory-deadline advice under the U.K. HGCRA 1996, Scheme for Construction Contracts 1998, Irish Construction Contracts Act 2013, Australian SoP Acts, U.S. Miller Act, U.S. state prompt-payment acts, U.S. state mechanic's-lien laws or German BGB / VOB/B / BauFordSiG regimes;
• AI RICS / CIOB / CIArb / RIBA / CIBSE / CABE / ICE / IStructE / CIPHE / IOR / AIQS / AIB / NZIQS / ASPE / AIC / VOB professional-body attestations;
• AI CDM 2015 / HSE / OSHA / BauFordSiG / Arbeitsschutzgesetz / Baustellenverordnung / U.K. Building Safety Act 2022 / Gateway 2 / Gateway 3 / Higher-Risk Buildings duty-holder submissions;
• AI planning-permission, Building Regulations, listed-building-consent, Regulatory Reform (Fire Safety) Order 2005, Fire Safety (England) Regulations 2022 or NFCC authorisations;
• AI JCT / NEC / FIDIC / IChemE / ACA / GC Works / ConsensusDocs / AIA / VOB/B / AS 4000 / AS 2124 contract-clause interpretation;
• AI Construction Industry Scheme (CIS) / IR35 / off-payroll-working / prevailing-wage / Davis-Bacon / Fair Wages / apprenticeship-levy determinations;
• AI Modern Slavery Act 2015, EU CSDDD, German LkSG, Norwegian Åpenhetsloven, Australian Modern Slavery Act 2018 or California Transparency in Supply Chains Act declarations;
• AI U.K. Bribery Act 2010, U.S. FCPA, OECD Anti-Bribery Convention, 5AMLD, 6AMLD, U.K. Money Laundering Regulations 2017, U.S. Bank Secrecy Act, OFAC, EU Consolidated, U.K. OFSI or U.N. sanctions / PEP determinations;
• AI insurance underwriting or claims determinations by any insurer;
• AI worker-performance, employability, ranking, blacklist, timeliness, quality-of-work, quality-of-QS, quality-of-adjudicator, quality-of-insurer, counterparty-risk or claim-outcome-prediction profiles of any owner, foreman, apprentice, labourer, hired-in operative, head-contractor QS, adjudicator, insurer, claims consultant, employer's agent, project manager, engineer, subcontractor, supplier, delivery driver, site visitor or any other individual (no worker-performance scoring of any kind); or
• Any AI feature that requires transmission of Customer Data off-device to a third-party model provider. Foundation Models is Apple's on-device large-language-model framework; Vision is on-device; Speech-framework transcription runs on-device; there is no ML-Consulting-hosted backend model and no Anthropic / OpenAI / Whisper / Google / Meta model in the ClaimLedger data plane.
14.3 On-device Foundation Models, Vision, Speech and PhotoKit
The App includes on-device Foundation Models dictation structuring (with plain Speech-framework transcript fallback below the device floor), on-device Vision-framework OCR (v1.1), on-device Speech-framework recognition and on-device PhotoKit access. These run locally on your iPhone or iPad and the input is not transmitted to any third-party AI provider as a result of these features. The recorder or Owner must confirm every structured field before it becomes an evidentiary entry, and the raw dictation transcript or raw OCR text is always retained alongside any structured output.
14.4 Deterministic on-device engines (not AI)
Three important on-device engines in ClaimLedger are DETERMINISTIC and not AI at all: the Pack completeness-check engine; the hidden-works follow-up scheduler; and the append-only supersede-chain evidence integrity engine. These engines are pure, unit-tested Swift code; their output is fully explainable by inspection of the code and the Customer Data; and they never block Pack generation — they inform, they never gate.
14.5 EU AI Act readiness
We design and operate the App's on-device AI features to be compatible with applicable obligations under Regulation (EU) 2024/1689 (the AI Act), including transparency (the raw input is always retained alongside any structured output; the recorder always confirms), logging (any AI-structured entry records the model version that produced it, and Foundation Models version is disclosed in release notes) and human-oversight requirements. None of the current AI features is, or is held out as, a high-risk AI system within the meaning of Annex III of the AI Act.
15. How long we keep personal data
We keep personal data only for as long as we need it for the purpose for which it was collected, or as required by applicable law. Because Customer Data lives in the Subscribing Customer's own iCloud, ClaimLedger cannot itself delete Customer Data from your iCloud — you (and Apple) do that.
• Account and authentication data (we act as controller): lifetime of the App Store subscription plus the App Store-controlled refund window; in any case deleted or anonymised within 24 months of complete inactivity, save where statutory retention applies.
• Device, technical and telemetry data (limited): where visible to us at all, retained in identifiable form for a maximum of 13 months; aggregated or anonymised data may be retained indefinitely.
• Communications and support correspondence: up to 24 months from the close of the last related correspondence; longer where the matter relates to a complaint, App Store subscription dispute, statutory-adjudication counterclaim, insurance subrogation, HSE / OSHA / CDM 2015 investigation, BauFordSiG investigation, U.K. Building Safety Act 2022 investigation or class-action investigation.
• Billing, accounting and tax records: up to 10 years from the end of the relevant accounting period, in line with Lithuanian financial-accounting and tax-administration law.
• Customer Data on your own iCloud (we act as processor in the narrow sense): retained on the Subscribing Customer's iCloud for as long as the Owner keeps it. Post-trial the App is read-only with export always available; the Owner's data is never held hostage. On App deletion the on-device store is removed by iOS. On Owner deletion of the company (Settings), the App offers a full export, then removes the local store and the CloudKit zone (and, from v1.1, the CKShare share).
• Foreman participant data (v1.1): a participant's Evidence entries remain in the Owner's zone if the Owner removes the participant. A participant leaving the share does not touch company data.
• PackRecord entries and PDF Pack renders: retained on the Subscribing Customer's iCloud for as long as the Owner keeps them; append-only by design.
• Backups (Apple iCloud backup): Apple's iCloud backup rotation applies; ML Consulting does not operate a separate backup and does not restore deleted accounts.
16. Security and personal-data breaches
16.1 Article 32 measures
We implement and maintain appropriate technical and organisational measures to protect personal data — particularly the narrow controller-level data we hold — against unauthorised access, accidental loss, destruction, alteration or disclosure (Article 32 GDPR). For ClaimLedger specifically, these measures include: iOS application-sandbox isolation and Apple's default Data Protection; CryptoKit SHA-256 per-photo hashing at capture time before the UI unblocks; append-only supersede-chain evidence integrity; optional Face ID / Touch ID biometric gating of Pack generation, PencilKit handover-signature capture and Pack-share confirmations; Keychain-scoped short secrets; watermarking and version-stamping on every Pack; a mandatory disclaimer footer on every Pack; a per-Pack photo-hash manifest; the Privacy Manifest declaration; and — for the Customer Data itself — Apple's iCloud in-transit and at-rest encryption on the Subscribing Customer's own iCloud.
16.2 Notification of personal-data breaches
If we become aware of a personal-data breach that is likely to result in a risk to the rights and freedoms of natural persons in respect of the narrow controller-level data we hold, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach (Article 33 GDPR). Where the breach is likely to result in a high risk, we will notify the affected data subjects without undue delay (Article 34 GDPR). Because Customer Data lives in the Subscribing Customer's own iCloud, an iCloud-side security incident is handled by Apple under Apple's own breach-notification obligations.
16.3 Reporting a suspected breach to us
If you suspect a security incident or unauthorised access affecting your account, device, App Store subscription, Sign in with Apple identifier, PencilKit handover signature, Pack PDF, PackRecord or biometric-verification metadata, please notify us at support+claimledger@mlconsulting.lt without undue delay. Provide as much detail as you can; do not include passwords or other secrets in the email.
17. Your rights as a data subject
Subject to the conditions set out in the GDPR, you have the rights below. These rights are not absolute and may be restricted by law. Because Customer Data lives in your own iCloud, several of these rights are exercised most efficiently through Apple (iCloud account controls, Data & Privacy portal at privacy.apple.com) rather than through ML Consulting.
• Right of access (Article 15) — confirm whether we process personal data about you and obtain a copy. Note that ML Consulting itself holds only the narrow controller-level data described in section 4.1; the bulk of your Customer Data lives in your own iCloud and is accessible to you through the App and through Apple.
• Right to rectification (Article 16) — have inaccurate personal data corrected and incomplete data completed. In the App itself, evidence entries and photos are immutable after save — corrections supersede and both remain visible.
• Right to erasure (Article 17) — have personal data erased where the conditions apply. For controller-level data ML Consulting holds, this is a direct request to us. For Customer Data on your own iCloud, use the App's in-Settings Company Deletion flow (which offers full export before removing the local store, the CloudKit zone and any v1.1 CKShare share).
• Right to restriction of processing (Article 18) — restrict our processing while we verify contested data or deal with an objection.
• Right to data portability (Article 20) — receive the data you provided in a structured, commonly-used and machine-readable format. The App provides in-Settings full export at any time, including post-trial (data is never hostage).
• Right to object (Article 21) — object to processing based on legitimate interests on grounds relating to your particular situation, and at any time to direct marketing.
• Rights related to automated decision-making (Article 22) — not be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects. See section 14 and the explicit AI exclusions.
• Right to withdraw consent (Article 7(3)) — where we rely on consent, withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
• Right to lodge a complaint (Article 77) — complain to our lead supervisory authority, the VDAI in Vilnius, or to the supervisory authority of the EU Member State where you habitually reside, where you work or where the alleged infringement took place.
17.1 How to exercise your rights
You can exercise the rights above by sending an email to support+claimledger@mlconsulting.lt with the words “Privacy request — ClaimLedger” in the subject line. For rights that concern data in your own iCloud, we may redirect you to Apple's Data & Privacy portal at privacy.apple.com.
We will respond to verifiable requests without undue delay and in any event within one month of receipt under Article 12(3) GDPR. We may extend that period by up to a further two months for complex or numerous requests. We may need to verify your identity proportionate to the request and the data concerned.
17.2 Workspace-controlled data — foreman participants and Recipients
For Customer Data that we process as processor on behalf of a Subscribing Customer — including data about the Owner, foreman participants (v1.1), and any individual identifiable in an Evidence entry, Pack PDF or handover signature — please direct your request to the Owner (Subscribing Customer) first; if you cannot identify the Owner, contact us at support+claimledger@mlconsulting.lt and we will redirect your request without undue delay. Recipients of Pack PDFs hold those PDFs as independent controllers.
18. Regional rights notices
18.1 United Kingdom — UK GDPR, ICO, HSE, CDM 2015, HGCRA 1996, Building Safety Act 2022
If you are in the United Kingdom, the UK General Data Protection Regulation and the UK Data Protection Act 2018 apply. The UK supervisory authority is the Information Commissioner's Office (ICO). The U.K. Housing Grants, Construction and Regeneration Act 1996 (as amended by LDEDCA 2009), the Scheme for Construction Contracts (England and Wales) Regulations 1998 and Scottish / Northern Irish equivalents, the CDM 2015 Regulations, the Health and Safety at Work etc. Act 1974, the MHSWR 1999, the Building Safety Act 2022 and Higher-Risk Buildings regime, the Fire Safety (England) Regulations 2022, the Regulatory Reform (Fire Safety) Order 2005, the Construction Industry Scheme (CIS), Sections 14-22 of the Consumer Rights Act 2015 and the U.K. Modern Slavery Act 2015 apply to U.K. Projects independently of the App.
18.2 Republic of Ireland — DPC, HSA, WRC, Construction Contracts Act 2013
If you are in the Republic of Ireland, the GDPR and the Irish Data Protection Act 2018 apply. The Irish supervisory authority is the Data Protection Commission (DPC). The Irish Construction Contracts Act 2013, the Safety, Health and Welfare at Work Act 2005 and Regulations 2013, the Building Control Acts, the Fire Services Acts, the Employment Relations Acts and the Workplace Relations Commission (WRC) apply to Irish Projects independently of the App.
18.3 Australia — OAIC, Safe Work Australia, state SoP Acts
If you are in Australia, the Australian Privacy Principles (APPs) and the Privacy Act 1988 apply. The Australian supervisory authority is the Office of the Australian Information Commissioner (OAIC). The Building and Construction Industry Security of Payment Acts of NSW (1999), Victoria (BIF Act 2020), Queensland (BIF Act 2017), Western Australia (CCA 2004), South Australia (BCISP Act 2009), Tasmania (BCISP Act 2009), Northern Territory (CCSPA 2004) and the Australian Capital Territory (BCISP Act 2009), the Work Health and Safety Acts and Regulations, the Fair Work Act 2009, the state workplace-surveillance Acts, the National Construction Code (NCC) and the Australian Modern Slavery Act 2018 apply to Australian Projects independently of the App.
18.4 United States — CCPA / CPRA, OSHA, Miller Act, state prompt-payment and mechanic's-lien laws
If you are a California resident, the CCPA / CPRA gives you the rights described in the corresponding section. We do not sell personal information and we do not “share” personal information for cross-context behavioural advertising. The U.S. OSHA 29 CFR §1926 (construction), the Miller Act (40 U.S.C. §§ 3131-3134), state prompt-payment acts, state mechanic's-lien laws, state licensing statutes, the National Labor Relations Act, state consent-to-record wiretap laws and the California Transparency in Supply Chains Act apply to U.S. Projects independently of the App. Similar privacy rights are available to residents of Colorado, Connecticut, Virginia, Utah, Texas, Florida, Oregon, Washington and other US states with comprehensive privacy laws.
18.5 Germany — BfDI, Land DPAs, BGB / VOB/B / BauFordSiG / LkSG
If you are in Germany, the GDPR and the Bundesdatenschutzgesetz (BDSG) apply; the relevant Land DPA (or BfDI for federal contexts) is the supervisory authority. The BGB §§ 631 ff., VOB/B, BauFordSiG, Bauhandwerkersicherungshypothek, Baustellenverordnung, Arbeitsschutzgesetz, Betriebsverfassungsgesetz, Berufsgenossenschaft der Bauwirtschaft (BG BAU) and Lieferkettensorgfaltspflichtengesetz (LkSG) apply to German Projects independently of the App.
18.6 Global Privacy Control
On the App's landing pages, we honour the Global Privacy Control signal where technically feasible, treating it as an objection to non-essential cookies and a request to opt out of any “sale” or “sharing” of personal information.
19. Children
ClaimLedger is intended for business users (B2B) only and is not designed for use by minors. Users must be at least 18 years old, and any foreman participant added under v1.1 must be at least 18 and hold the site inductions, CDM 2015 / HSE / OSHA / BauFordSiG training, plant / tool licences and CSCS / CCNSG / SafePass / White Card credentials appropriate to the site. Apple's App Store age rating reflects the relevant minimum age for the App. If we become aware that we have collected personal data from a child without the appropriate authorisation, we will work with the relevant Subscribing Customer to investigate and, where appropriate, erase the data. If you are a parent or guardian and believe your child has provided personal data to us, please contact us at support+claimledger@mlconsulting.lt.
20. Cookies and similar technologies
The ClaimLedger iOS / iPadOS App does not use analytics, advertising, profiling or marketing cookies. The App uses on-device storage (the iOS application sandbox, the Keychain, SwiftData / CloudKit private database, UserDefaults) to deliver its features. This is not “cookies” within the meaning of the ePrivacy Directive 2002/58/EC.
The App's landing pages on mlconsulting.lt use only strictly-necessary cookies. No analytics or advertising cookies are set. Because there is no direct billing channel and no Stripe billing pages for ClaimLedger, there are no third-party payment cookies to disclose either.
21. Communications
21.1 Service messages
We send transactional service messages (security alerts, App Store billing notices via Apple, support replies, material change notices) on the basis of contract performance under Article 6(1)(b) GDPR. Service messages are not commercial marketing and cannot be opted out of without ceasing to use the App.
21.2 Direct marketing
Where we send commercial marketing emails about ClaimLedger — product updates, launch announcements, educational materials on subcontract payment evidence, or event invitations — we rely either on (i) your prior consent under Article 6(1)(a) GDPR and Article 13 of the ePrivacy Directive, or (ii) the “soft opt-in” under Article 13(2) of the ePrivacy Directive. You may opt out at any time by clicking the unsubscribe link in any marketing email, by emailing support+claimledger@mlconsulting.lt or by updating your preferences.
21.3 Operational notifications — not statutory-deadline advice
Local-notification cadence (application-day 3-days-before and day-of reminders per Project; hidden-works follow-up notifications; trial-day-11 and trial-day-13 reminders; optional daily-log nudges), ActivityKit Live Activities (Owner-started dispute-window countdown with Owner-entered dates), Dynamic Island indicators, WidgetKit Lock-Screen widgets and App Intents / Siri shortcuts are operational reminders configured by you. They are best-effort and depend on Apple's platform services. They are NOT statutory-deadline advice, NOT a computed adjudication deadline under HGCRA 1996 / Scheme for Construction Contracts 1998 / Irish CCA 2013 / Australian SoP Acts / U.S. Miller Act / state prompt-payment or mechanic's-lien laws / German BGB / VOB/B / BauFordSiG, NOT an RICS quantity-surveyor's opinion, NOT a CIArb arbitrator's ruling, NOT a court order, NOT a Qualified Trust Service Provider attestation, NOT a fire alarm, NOT an intrusion alarm, NOT a calibrated instrument reading and NOT a 999 / 112 / 911 / 000 dispatch. CALL 999 / 112 / 911 / 000 OR THE LOCALLY APPLICABLE PUBLIC EMERGENCY NUMBER FIRST whenever any person is in apparent danger of death or serious harm on site.
22. Changes to this Policy
22.1 Routine updates
We may update this Policy from time to time, for example to reflect new features (v1.1 CKShare team workspaces, v1.1 Vision OCR, v1.5+ RoomPlan), regulatory developments, Apple platform changes (Foundation Models version updates) or operational changes. The latest version is always published on the App's App Store listing and at mlconsulting.lt/claimledger/privacy.
22.2 Material changes
Where a change is material and adversely affects your rights or expectations, we will give reasonable advance notice — typically at least 30 days, unless a shorter period is required by law, by Apple App Store policy or to address a security risk — by in-app notice and, where we have your email address, by email. Non-material changes take effect on posting.
22.3 Versioning
Each version of this Policy is dated and archived. The version in force at the time of the relevant processing governs that processing. The Foundation Models model version in use at any given time is disclosed in the App's release notes.
© 2026. All rights reserved.
